portraitureplugin2342.exe

Project1

The executable portraitureplugin2342.exe has been detected as malware by 8 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.imagenomic.com.
Product:
Project1

Version:
1.00

MD5:
e90f9d86ec2a2dc49d04a63b9e0b9036

SHA-1:
4b539f810a2c3c8036f39db057f1a4396bf98727

SHA-256:
44f39c02f07696eb54aeff225b0359617acbc6cebdd6a7e6fa5ed30195753c92

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
4/24/2024 4:51:37 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:VB-OJQ [Wrm]
160503-1

Emsisoft Anti-Malware
Gen:Variant.Kazy.670493
11.5.0.6191

ESET NOD32
Win32/VB.QOT trojan
7.0.302.0

F-Secure
Variant.Razy.42892
5.15.96

Kaspersky
Trojan.Win32.Agent
15.0.0.562

McAfee
Virus.W32/Swisyn.ai
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.2471.0

Norman
Gen:Variant.Razy.42892
19.05.2016 05:17:13

File size:
4.1 MB (4,341,511 bytes)

Product version:
1.00

Original file name:
TJprojMain.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\portraitureplugin2342.exe

File PE Metadata
Compilation timestamp:
3/29/2013 6:43:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:2WSmEB6j3VApmfTfSwppjo3PQHJfx9zW/M04KBg+BTT+jSR:2WH3hfTfjppj8PQHJJBUMoBnOm

Entry address:
0x282C

Entry point:
68, FC, 39, 40, 00, E8, EE, FF, FF, FF, 00, 00, 48, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 04, 7D, 33, EB, 79, F0, F3, 42, B6, 9B, CD, 75, 39, 6A, 05, 87, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 20, 20, 27, 46, 6C, 61, 50, 72, 6F, 6A, 65, 63, 74, 31, 00, 6B, 43, 6F, 6C, 6F, 72, 20, 00, 20, 20, 20, 20, 20, 3D, 20, 00, 00, 00, 00, 90, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 01, 00, 00, 00, 47, B9, 21, 88, 70, 8F, 72, 44, 84, A9, 83, FC, 14, 57, 21, 03, 01, 00, 00, 00, A0, 00, 00, 00...
 
[+]

Entropy:
7.9839

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
100 KB (102,400 bytes)

The file portraitureplugin2342.exe has been seen being distributed by the following URL.

Remove portraitureplugin2342.exe - Powered by Reason Core Security